Have you tried "set interface" instead of "set ip"?
Sent from my iPhone On Aug 12, 2010, at 3:13 PM, Andrey Khomyakov <khomyakov.and...@gmail.com> wrote: > I did try an extended ACL and had the same result. > The way I know that it's not working is that I see these packets arriving on > a wrong interface on the firewall and therefor being dropped. > I actually had to open a CR with Cisco and they verified the config and said > nothing is wrong with it. They are escalating and will hopefully get back to > me about this. > > Andrey